Wpseeds develops a focused line of WordPress plugins, including database backup and user management utilities, that command presence within the WordPress ecosystem. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring exposure centers on application-layer input-handling and request-validation weaknesses such as cross-site scripting, CSRF, OS command injection, and insufficient randomization that are common to server-side WordPress extensions. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpseeds over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25224CRITICAL The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attac | Jul 25, 2025 | 9.8 | 55 | NO | YES |
CVE-2016-10874HIGH The wp-database-backup plugin before 4.3.3 for WordPress has CSRF. | Aug 12, 2019 | 8.8 | 26 | NO | NO |
CVE-2020-7241HIGH The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP a | Jan 20, 2020 | 7.5 | 25 | NO | NO |
CVE-2016-10876HIGH The wp-database-backup plugin before 4.3.1 for WordPress has CSRF. | Aug 12, 2019 | 8.8 | 25 | NO | NO |
CVE-2019-14949MEDIUM The wp-database-backup plugin before 5.1.2 for WordPress has XSS. | Aug 12, 2019 | 6.1 | 21 | NO | NO |
CVE-2016-10875MEDIUM The wp-database-backup plugin before 4.3.1 for WordPress has XSS. | Aug 12, 2019 | 6.1 | 21 | NO | NO |
CVE-2022-4519MEDIUM The WP User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 7.0 due to insufficient input sanitizati | Dec 15, 2022 | 4.8 | 19 | NO | NO |
CVE-2016-10873MEDIUM The wp-database-backup plugin before 4.3.3 for WordPress has XSS. | Aug 12, 2019 | 6.1 | 19 | NO | NO |
CVE-2022-2271MEDIUM The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting | Sep 5, 2022 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpseeds.
Media articles that mention a CVE ID that affects a product developed by Wpseeds — matched by CVE ID, not by vendor name.